Physical and Environmental Protection Policy

This policy establishes the requirements for protecting physical assets, facilities, and information systems from unauthorised access, damage, theft, and environmental threats. It outlines the controls needed to maintain secure premises, safeguard critical equipment, and support the ongoing availability and protection of organisational resources.

Description

This policy establishes a framework for controlling physical access to organisational facilities, protecting equipment and infrastructure, monitoring environmental conditions, and implementing measures to prevent damage, disruption, theft or unauthorised access. It supports the security and availability of information systems through the application of physical and environmental protection controls.

Aligned to the NIST Cybersecurity Framework (CSF) and informed by NIST SP 800-53 security controls, it helps organisations implement industry-recognised security governance practices.

Our policy templates are designed by experienced cybersecurity consultants to accelerate policy development and security program maturity.

Rather than starting from a blank page, you can leverage a professionally developed policy and tailor it to suit your organisation’s specific requirements, operating environment, and risk profile.

The policy is provided in Microsoft Word format. ready for customisation and implementation.

Table of Contents

This policy is suitable for organisations seeking to establish or mature their cybersecurity governance framework and risk management practices, including:

  • Small to medium enterprises implementing formal cybersecurity governance
  • Organisations preparing for audits, certifications, or regulatory obligations
  • Organisations adopting the NIST Cybersecurity Framework (CSF), NIST SP 800-53 or NIST best practices
  • Security, risk, compliance, and governance teams

The policy includes guidance on:

  • Physical access control and facility security management
  • Authorised access, access credential management, and periodic access reviews
  • Visitor management, escorting, monitoring, and record retention
  • Physical security monitoring, surveillance systems, and intrusion detection
  • Protection of system distribution and transmission infrastructure
  • Control of physical access to information system outputs and devices
  • Physical security incident detection, investigation, and response coordination
  • Security of power equipment, cabling, and emergency power shutoff mechanisms
  • Uninterruptible power supply (UPS) and continuity of operations during power outages
  • Emergency lighting, fire detection, and fire suppression controls
  • Environmental monitoring, including temperature and humidity management
  • Protection against water damage and environmental hazards
  • Control and tracking of system components entering and leaving facilities
  • Security requirements for alternate work locations and remote worksites
  • Assessment and implementation of physical and environmental safeguards
  • Compliance with physical and environmental protection requirements and controls
  • Aligned to the NIST Cybersecurity Framework (CSF)
  • Mapped to relevant NIST SP 800-53 security controls
  • Reduces the time and effort required to develop policies from scratch
  • Supports consistent security governance practices across the organisation
  • Helps demonstrate due diligence to customers, auditors, regulators, and stakeholders
  • Provides a strong foundation for cybersecurity risk management and continuous improvement
  • Delivered in an editable Microsoft Word format for easy customisation
  •  
  1. Replace your organisation’s details, branding, and logo where indicated.
    1. Update all content contained within [square brackets].
    2. Review highlighted or guidance text and customise where appropriate.
  2. Review the policy and tailor the content to your organisation’s structure, risk profile, and objectives.
  3. Publish the finalised policy and communicate it to relevant stakeholders.

How It Works

White number 1 inside an orange circle

Select and Download Your Module

Pick the modules you need, download instantly, and own them for life—no subscriptions, no ongoing costs.

White number 2 inside a magenta circle

Upload the Module to Your LMS

Drop the SCORM files into your existing LMS. Fast, seamless integration with most major platforms.

A white number 3 in the middle of a blue circle.

Train Your Staff - Protect Your Organisation

Engaging content your team will remember. Track completions and compliance with ease.

Test Your LMS Here

Click here to be redirected to our free video for you to download and test in your LMS.

Frequently Asked Questions

Whether you’re wondering about how our modules work, how to integrate them with your LMS, or what’s included in each purchase, our FAQs below have you covered.

We are committed to staying current with cybersecurity trends and threats. Our content is regularly updated to reflect the latest developments, ensuring your team learns the most relevant information.

Absolutely. Our training modules are designed to cater to all levels of expertise. We use simple language and relatable scenarios to make the content accessible and valuable for both technical and non-technical staff.

Yes. All our modules are SCORM-compliant and designed for seamless integration with most learning management systems.

No problem! There are several free or cost-effective LMS options available that could work well for your training needs if you don’t have your own LMS.  Open-source platforms like Google Classroom and Moodle are popular choices that many organisations use successfully for security awareness training.  Microsoft Viva Learning may also be an option, depending on your current licencing. 
 
Once you have a preferred LMS in place, our training modules integrate easily, and you will have a complete training solution. 

A SCORM file (Sharable Content Object Reference Model) is a standardized package of eLearning content that can be uploaded into a Learning Management System (LMS). It allows for consistent delivery, tracking, and reporting of training modules across different platforms. 

We use SCORM 1.2, the most widely supported version across LMS platforms. 

Absolutely. Each product page includes a short preview video showcasing the module’s style, tone, and key content.

Our products are sent out in SCORM 1.2 format, which is compatible with most Learning Management Software. However, we have created a free video for you to download and test in your LMS which you can find in the shop under “LMS Test Video”.

We aim to meet core accessibility requirements, including captions, clear audio, and readable text. While not fully WCAG-certified, our modules are designed with inclusivity in mind.

Our modules cover core cyber security awareness topics, including phishing, social engineering, safe web browsing, data protection, password hygiene, and more. View our Shop for full training catalogue for details.

Absolutely! Our modules are designed for businesses of all sizes with no ongoing licensing fees or user limits – your costs stay predictable as you grow.  

Whether you’re a small team or large enterprise, educated employees are your most effective security control.

Yes. All videos include closed captions to support accessibility and improve comprehension for all learners. Captions are embedded and meet common accessibility standards.

No. Once you purchase a module, you can deploy it to as many users as your LMS allows — no user limits or ongoing costs.

This website uses cookies to ensure you get the best experience from our website.  Learn More